IT & Digital Services
Your customers check you before the regulator does.
Managed service providers, data centres, cloud and software vendors sit on two fronts: obligations of their own under NIS2 — and the requirements of every customer who is themselves covered and has to check their own supply chain.
Does this apply to you?
Annex 1 · Sector 6 (digital services: Annex 2 · Sector 6)
Sector: Digital infrastructure
Cloud computing and data centre services, managed service providers and managed security service providers, internet exchange points, DNS services, TLD registries, content delivery networks, trust service providers, and telecommunications networks and services. Online marketplaces, search engines, and social networks sit in Annex 2.
Entity of essential importance
at least 250 employees — or annual turnover above €50 million and an annual balance sheet total above €43 million
Applies to entity types under Annex 1 · Section 28(1), (2) BSIG
Important entity
at least 50 employees — or annual turnover and balance sheet total above €10 million
Applies to entity types under Annexes 1 and 2 · Section 28(1), (2) BSIG
Important for you: Covered without any size threshold: qualified trust service providers, TLD registries, and DNS service providers (Section 28(1) No. 2 BSIG). Telecoms providers also have their own separate thresholds (50 employees, or €10 million).
Covered regardless of size: operators of critical facilities, qualified trust service providers, top-level domain registries, and DNS service providers (Section 28(1) Nos. 1, 2 BSIG); trust service providers always count as an important entity (Section 28(2) No. 1 BSIG). Employee count and financial figures are alternative thresholds (either one triggers coverage); for the financial figures, both values must be exceeded. Whether your specific company is covered is a case-by-case question — that's what lawyers are for.
What's typically in the register in this sector
These obligations decide it for you.
Section 30(2) No. 10 BSIG
Privileged access is your biggest risk
Multi-factor or continuous authentication and secured communications: whoever has admin rights at your organisation has them across every one of your customers too.
Section 30(2) No. 5 BSIG
Manage and disclose vulnerabilities
Secure acquisition, development, and maintenance — including vulnerability management and disclosure. For software vendors, this is the core discipline.
Section 30(2) No. 4 BSIG
Evidence your customers can pass along
Your customers have to govern the security-relevant aspects of their relationship with you — the better your evidence, the shorter their review, and the more secure your contract.
Example (fictional): The MSP that became a disqualifying factor
An IT service provider supports 60 mid-sized clients. Two of them fall under NIS2 themselves and have to review their supply chain. They send the same questionnaire — both asking for evidence on access control, incident reporting, and training status.
The provider can explain all of it, but show none of it. One client postpones the contract renewal; the other demands a remediation deadline. The competitor's bid was priced higher — but came with a linkable trust centre attached.
A freely invented example for illustration — no real customer, no legal advice
Here's how Compliverse takes this off your plate.
- 1
Your own trust centre builds itself from fulfilled obligations — linkable, not assembled from scratch each time.
- 2
Per-person training records, exportable for every customer audit.
- 3
One action plan that pays into NIS2, ISO 27001, and GDPR at the same time — instead of three separate projects.
NIS2 in IT & Digital Services: frequently asked questions
Is my IT & Digital Services company in scope for NIS2?
Your sector is covered by Germany's BSI Act: Annex 1 · Sector 6 (digital services: Annex 2 · Sector 6), sector Digital infrastructure. That does not put you in scope automatically — a size threshold has to be met as well (Section 28(1), (2) BSIG). And no official notice arrives: you assess the classification yourself and register if it applies (Section 33 BSIG). Your sector also has an exception — it is set out on this page under “Are you in scope?”. Judging your individual case is a lawyer's job.
From what size does NIS2 apply to us?
You count as an essential entity from at least 250 employees — or annual turnover above €50 million and an annual balance sheet total above €43 million; as an important entity from at least 50 employees — or annual turnover and balance sheet total above €10 million (Section 28(1), (2) BSIG). Headcount and financial figures are alternatives to each other — but where the financial figures are used, both have to be exceeded. Some entity types are in scope regardless of size, among them operators of critical facilities and qualified trust service providers.
Which authority is responsible for us in Germany?
Registration and supervision sit with the Bundesamt für Sicherheit in der Informationstechnik (BSI) — Germany's Federal Office for Information Security (Section 33 BSIG). Security incidents, however, do not go there: they go to the joint reporting office of the BSI and the Federal Office of Civil Protection and Disaster Assistance (BBK) — early warning within 24 hours, report within 72 hours, follow-up report a month later (Section 32 BSIG). This is the most common misreading of the act — the supervisory authority and the reporting office are not the same body.
What happens if we do not implement NIS2?
The obligations do not go away: registration stays due (Section 33 BSIG), so do the risk-management measures (Section 30(2) BSIG), and reporting deadlines start running with the first significant incident (Section 32 BSIG). On top of that, Section 38 BSIG puts management personally on the hook: they have to approve the measures, oversee their implementation, and undergo training themselves. “I didn't know” does not carry here.
Find out in thirty seconds what applies to you.
Four questions, an honest first estimate — then you'll know which module to start with and what it costs.
What becomes important next
More industries
Legal status checked on 01/09/2026 · Every statement with a source · No legal advice